Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-12087: Perl packages on Debian could let attackers run code
CVE-2026-12087 · published today
Summary
The Perl and related library packages for Debian (including libsocket-perl and rootio-perl) have a flaw that could allow an attacker to execute commands on your system. This can compromise the confidentiality and integrity of your data. Apply the latest updates from your package manager to install the patched versions as soon as possible.
What to do
- Update debian libsocket-perl to version 2.041-1.
- Update canonical perl to version 5.18.2-2ubuntu1.7+esm8.
- Update canonical perl to version 5.22.1-9ubuntu0.9+esm3.
- Update canonical perl to version 5.26.1-6ubuntu0.7+esm3.
- Update canonical perl to version 5.30.0-9ubuntu0.5+esm3.
- Update canonical perl to version 5.34.0-3ubuntu1.8.
- Update canonical perl to version 5.38.2-3.2ubuntu0.4.
- Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.11.
- Update debian rootio-perl to version 5.40.1-6.root.io.5.
- Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.12.
- Update debian perl to version 5.36.0-7+deb12u3.root.io.12.
- Update debian perl to version 5.32.1-4+deb11u5.root.io.5.
- Update debian perl to version 5.40.1-6.root.io.5.
- Update debian rootio-perl to version 5.32.1-4+deb11u5.root.io.5.
- Update debian perl to version 5.42.3-1.
- Update perl to version 5.40.1-6.aikido.10.
- Update rootio-perl to version 5.40.1-6.aikido.10.
- Update perl to version 5.36.0-7+deb12u3.aikido.19.
- Update rootio-perl to version 5.36.0-7+deb12u3.aikido.19.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:12 | debian | libsocket-perl | All versions |
| Debian:13 | debian | libsocket-perl | All versions |
| Debian:14 | debian | libsocket-perl |
< 2.041-1 Fix: upgrade to 2.041-1
|
| Debian:11 | debian | perl | All versions |
| Debian:12 | debian | perl | All versions |
| Debian:13 | debian | perl | All versions |
| Debian:14 | debian | perl |
< 5.42.3-1 Fix: upgrade to 5.42.3-1
|
| Ubuntu:Pro:14.04:LTS | canonical | perl |
< 5.18.2-2ubuntu1.7+esm8 Fix: upgrade to 5.18.2-2ubuntu1.7+esm8
|
| Ubuntu:Pro:16.04:LTS | canonical | perl |
< 5.22.1-9ubuntu0.9+esm3 Fix: upgrade to 5.22.1-9ubuntu0.9+esm3
|
| Ubuntu:16.04:LTS | canonical | libsocket-perl | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | perl |
< 5.26.1-6ubuntu0.7+esm3 Fix: upgrade to 5.26.1-6ubuntu0.7+esm3
|
| Ubuntu:18.04:LTS | canonical | libsocket-perl | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | perl |
< 5.30.0-9ubuntu0.5+esm3 Fix: upgrade to 5.30.0-9ubuntu0.5+esm3
|
| Ubuntu:20.04:LTS | canonical | libsocket-perl | All versions |
| Ubuntu:22.04:LTS | canonical | libsocket-perl | All versions |
| Debian:11 | debian | libsocket-perl | All versions |
| Ubuntu:22.04:LTS | canonical | perl |
< 5.34.0-3ubuntu1.8 Fix: upgrade to 5.34.0-3ubuntu1.8
|
| Ubuntu:24.04:LTS | canonical | libsocket-perl | All versions |
| Ubuntu:24.04:LTS | canonical | perl |
< 5.38.2-3.2ubuntu0.4 Fix: upgrade to 5.38.2-3.2ubuntu0.4
|
| Ubuntu:25.10 | canonical | libsocket-perl | All versions |
| Ubuntu:25.10 | canonical | perl | All versions |
| Ubuntu:26.04:LTS | canonical | libsocket-perl | All versions |
| Ubuntu:26.04:LTS | canonical | perl | All versions |
| Root:Debian:12 | debian | rootio-perl |
< 5.36.0-7+deb12u3.root.io.11 < 5.36.0-7+deb12u3.root.io.12 Fix: upgrade to 5.36.0-7+deb12u3.root.io.11
|
| Root:Debian:13 | debian | rootio-perl |
< 5.40.1-6.root.io.5 Fix: upgrade to 5.40.1-6.root.io.5
|
| Root:Debian:12 | debian | perl |
< 5.36.0-7+deb12u3.root.io.12 Fix: upgrade to 5.36.0-7+deb12u3.root.io.12
|
| Root:Debian:11 | debian | perl |
< 5.32.1-4+deb11u5.root.io.5 Fix: upgrade to 5.32.1-4+deb11u5.root.io.5
|
| Root:Debian:13 | debian | perl |
< 5.40.1-6.root.io.5 Fix: upgrade to 5.40.1-6.root.io.5
|
| Root:Debian:11 | debian | rootio-perl |
< 5.32.1-4+deb11u5.root.io.5 Fix: upgrade to 5.32.1-4+deb11u5.root.io.5
|
| Root:Debian:13 | – | perl |
< 5.40.1-6.aikido.10 Fix: upgrade to 5.40.1-6.aikido.10
|
| Root:Debian:13 | – | rootio-perl |
< 5.40.1-6.aikido.10 Fix: upgrade to 5.40.1-6.aikido.10
|
| Root:Debian:12 | – | perl |
< 5.36.0-7+deb12u3.aikido.19 Fix: upgrade to 5.36.0-7+deb12u3.aikido.19
|
| Root:Debian:12 | – | rootio-perl |
< 5.36.0-7+deb12u3.aikido.19 Fix: upgrade to 5.36.0-7+deb12u3.aikido.19
|
Original advisory text
CVE-2026-12087 in perl - Patched by Root
Root has patched CVE-2026-12087 in the perl package for Root:Debian:12. Multiple fixed versions available.
References
- https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.pa...
- https://metacpan.org/release/PEVANS/Socket-2.041/changes
- http://www.openwall.com/lists/oss-security/2026/06/15/10
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12087... Vendor Advisory
- https://ubuntu.com/security/CVE-2026-12087 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-12087 Third Party Advisory
- https://lists.security.metacpan.org/cve-announce/msg/41020451/ Third Party Advisory
- https://ubuntu.com/security/notices/USN-8675-1 Vendor Advisory
- https://ubuntu.com/security/notices/USN-8684-1 Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-12087 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-12087 Vendor Advisory
- https://cpan.org/modules URL
Severity
9.1
Critical
CVSS 3.1: 9.1 (OSV)
Exploitation
EPSS <1%
Type
CWE-125Out-of-bounds Read
CWE-805Buffer Access with Incorrect Length Value
Timeline
Published28 Sep 2026
Updated28 Sep 2026
First seen16 Jun 2026
Sources
CVE-2026-12087 · NVD
UBUNTU-CVE-2026-12087 · OSV
CVE-2026-12087 · OSV
DEBIAN-CVE-2026-12087 · OSV
Track software like this
Free during beta